Guides · Privacy Act

The Privacy Act just started applying to businesses that were always exempt. Yours might be one.

On 1 July 2026, Australia's new anti-money-laundering rules began applying to real estate agents, conveyancers, lawyers, accountants and several other professions. Buried inside that change is a second one almost nobody is talking about: those businesses now have Privacy Act obligations too — no matter how small they are. Here's what changed, who it covers, and what to do about it.

What happened on 1 July

Australia's anti-money-laundering law — the Anti-Money Laundering and Counter-Terrorism Financing Act (AML/CTF Act) — used to apply mainly to banks, casinos and money remitters. From 1 July 2026, it extends to a much wider group of ordinary businesses, known as "tranche 2" entities. According to AUSTRAC, the financial-crime regulator, that includes businesses providing certain designated services in:

If your business provides one of these services, the AML obligations are already live — they started on 1 July whether or not you've registered. And there's a date attached: AUSTRAC says newly regulated businesses that were providing a designated service on 1 July must enrol with AUSTRAC by 29 July 2026 — 28 days after the obligations commenced.

1 July 2026
Already in force
AML/CTF obligations began for tranche-2 businesses — and with them, Privacy Act obligations for the personal information handled to meet them.
29 July 2026
Enrolment deadline
Businesses providing a designated service on 1 July must apply to enrol with AUSTRAC by this date, via AUSTRAC Online.

The privacy change hiding inside it

Here's the part that has had far less attention. Most Australian small businesses — those with an annual turnover of $3 million or less — have never had to comply with the Privacy Act, thanks to the small business exemption. Many owners have reasonably filed privacy law under "doesn't apply to me".

That exemption has a list of exceptions, and one of them is now doing a lot of work: businesses with obligations under the AML/CTF Act. The OAIC's guidance for reporting entities puts it plainly: all reporting entities must comply with the Privacy Act when handling personal information for the purposes of, or in connection with, their AML/CTF obligations — "this includes those which are small businesses with an annual turnover of less than $3 million." From 1 July 2026, that captures the new tranche-2 businesses. Analysis by law firm HWL Ebsworth puts the number of small businesses affected at more than 100,000.

An important nuance — and one many summaries get wrong: the Privacy Act doesn't suddenly cover everything such a business does. Under section 6E(1A) of the Privacy Act, it applies to the activities carried on for the purposes of, or in connection with, your AML/CTF obligations — the customer identification, verification and due-diligence work the new law requires. In practice that's exactly the most sensitive information you'll hold: names, dates of birth, addresses, licence and passport details. Where the line falls for your particular business is a legal question worth asking a professional.

A real estate agency or accounting practice with a $500,000 turnover was outside the Privacy Act on 30 June. For its customer identification records, it isn't anymore.

The timing gives this extra weight. The OAIC reported this month that data breach notifications hit an all-time high in 2025 — 1,205 notifications, up 8% on the year before, with the majority caused by malicious or criminal attacks. The regulator now expects newly covered businesses to look after ID data properly, at exactly the moment attackers are targeting it hardest.

What you actually need to do

The AML program itself — risk assessments, customer due diligence, reporting — is a topic for AUSTRAC's own guidance and your professional advisers. What follows is the privacy side: the steps the OAIC's guidance describes, in plain English.

1

Work out whether you're covered

What: check whether anything you do is a "designated service" under the new rules. AUSTRAC has plain-language guidance by industry.

Why it matters: everything else flows from this. The definitions are specific — some real estate, legal and accounting work is captured and some isn't — and getting it wrong in either direction is costly.

How: start with AUSTRAC's "new to AUSTRAC" pages. If it's unclear whether your services are captured, this is worth having a professional review — it's a legal judgement, not a form-filling exercise.

2

Enrol with AUSTRAC — by 29 July if you were operating on 1 July

What: enrolment is done online through AUSTRAC Online. If you were providing a designated service on 1 July 2026, AUSTRAC's deadline to apply is 29 July 2026.

Why it matters: your obligations apply from 1 July regardless of whether you've enrolled — enrolling late doesn't pause them.

How: via AUSTRAC Online. It's free.

3

Publish (or update) a privacy policy

What: the Privacy Act requires a clearly expressed, up-to-date privacy policy explaining how you manage personal information — including what you collect for AML purposes, how it's held, used and disclosed.

Why it matters: for many tranche-2 businesses this is the first time a privacy policy has been a legal requirement rather than good practice. It's also the most visible signal to clients that you take their information seriously — and the OAIC notes that if you're otherwise exempt, the policy only needs to cover your AML-related information handling, not your whole business.

How: the OAIC's guidance lists what the policy should address. Put it on your website, link it in your footer, and date it.

4

Tell people what you're collecting, and why

What: before collecting personal information for AML purposes (or as soon as practicable afterwards), you must take reasonable steps to notify the person — what you're collecting, why, and who it may be disclosed to.

Why it matters: your clients are about to be asked for ID documents by businesses that never asked before. A short, honest collection notice turns a moment of friction into a moment of trust.

How: add a plain-English notice to your intake forms and onboarding emails. The OAIC guidance sets out the matters to cover.

5

Don't keep copies of ID documents you don't need

What: this surprises people: under the new rules, the AML/CTF Act does not require you to keep scanned copies or photocopies of ID documents for record-keeping. The OAIC says to record the details you need (name, date of birth, document number, what you did to verify) and take reasonable steps to destroy or de-identify full copies once they're no longer needed.

Why it matters: a folder of passport and licence scans is the single most damaging thing to lose in a breach. Every copy you don't keep is a copy that can't be stolen.

How: record details instead of keeping images wherever possible; where you do hold copies, store them securely and have a documented plan for destroying them when no longer needed. Details are in the OAIC guidance, including how it treats copies made under the old rules.

6

Secure it — and know what you'd do in a breach

What: you must take reasonable steps to protect the personal information you hold, and the OAIC expects you to have a data breach response plan. Businesses covered by the Privacy Act are also subject to the Notifiable Data Breaches scheme for that information.

Why it matters: the OAIC has said its expectations for a small business are scaled to its size and resources — but taking no steps is not reasonable for anyone. With breach notifications at a record high, "we're too small to be a target" is no longer a plan.

How: start with the basics you can do this week — unique passwords and multi-factor authentication on email and anywhere ID data lives, software updates, and knowing exactly where ID information is stored. The ACSC's small business cyber security guidance is free and written for non-technical owners.

What this guide is not

Precision matters more than drama here, so let's be exact about the edges.

  • This is not legal advice. Whether your services are "designated services", and exactly which of your activities the Privacy Act now touches, are legal questions about your specific business. This guide tells you the questions exist — a professional should answer them for you.
  • This is not the full removal of the small business exemption. A broader proposal to remove the $3 million exemption for all small businesses remains exactly that — a proposal, with no bill and no date. The change described here is narrower: it applies to businesses with AML/CTF obligations, for their AML-related information handling.
  • AegorIQ does not check AML compliance. We don't assess AML programs, customer due diligence or AUSTRAC enrolment — that's for AML professionals. What we check is your website's visible privacy and security posture, and we publish the complete list of what that means.

Where a website scan fits in

If your business is newly covered, the most visible part of your privacy posture is your website: whether a privacy policy exists at all, and whether it actually says what it needs to say. Two of the checks AegorIQ runs on every tier — including the free Scorecard — are exactly that: we check a privacy policy is present, and then we read it against the elements the Australian Privacy Principles expect: what you collect, whether it goes to third parties or overseas, how it's stored, how someone makes a complaint, and a last-updated date. We also check the basics that protect the information your clients send you — a valid HTTPS connection, email spoofing protections, and whether your contact details are reachable. A scan can't tell you whether you're an AML reporting entity. It can tell you whether the privacy policy you're now required to have is missing half its parts.

Sources

If you'd like a second pair of eyes

Is the privacy policy you now need actually complete?

The free Scorecard checks your live website — including whether a privacy policy is present and whether it covers what the Australian Privacy Principles expect — and emails you the result. No payment details, no obligation.